Summary
Togoder Security scanned the npm package npm@11.19.0 on Oct 6, 2026. An AI review of 142 source files produced 11 medium, 41 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 52
Dynamic module loading with computed input
NPS-22849B4B54B5
The defaultCommandLoader function uses require() with a template literal path constructed from the 'name' parameter. The 'name' value originates from docFile basenames and command loader inputs, which could potentially be manipulated to load unintended modules if the input is attacker-controlled. This is a common pattern but carries inherent risk of path traversal or arbitrary module loading.
Dynamic module loading with computed input
NPS-A1BB95051FCE
The getCommand function accepts an arbitrary 'name' and passes it to commandLoader, which by default executes require(../../lib/commands/${name}). Untrusted input to name could load unexpected modules. The name is derived from file basenames processed by this tooling, so exploitability depends on the inputs to the doc generation system.
Command/Process Execution
NPS-C9E1280C3CCF
Uses child_process.spawn to launch an external editor. The editor command is read from npm config ('editor'), which could be attacker-controlled if a malicious .npmrc is present, allowing arbitrary command execution.
Command/Process Execution
NPS-C3D20A5FD46E
Uses this.npm.exec('rebuild', [dir]) to execute npm's rebuild command, triggering lifecycle scripts (pre/postinstall) of packages in the edited directory, which is potentially dangerous if the package is untrusted.
process spawning / command execution
NPS-7B3A33CCC598
This is the npm exec command implementation, which intentionally spawns arbitrary shell commands and installs/executes packages via libnpmexec. The callExec method passes user-provided args, call, and packages into libexec, which will run scripts/commands. This is expected for npm exec, but it is inherently a high-privilege operation where user input leads to process execution.
Command execution via run-script
NPS-C0DF1E76231D
The code uses @npmcli/run-script to execute arbitrary commands from user-supplied arguments (args.join(' ')) as a package script named '_explore'. While this is the intended behavior of npm explore, it allows arbitrary command execution within the context of an installed package. This is not inherently malicious but is a high-risk pattern when analyzing third-party code.
process-spawning
NPS-AE5EDD968EF1
The class spawns external processes ('man', 'emacsclient') via '@npmcli/promise-spawn' in the viewMan method. Although this is legitimate help-viewing behaviour, it executes system commands. The 'emacsclient' invocation constructs an elisp expression using string interpolation with the man page path ((woman-find-file '${man}')), which could allow command injection if the path were attacker-controlled. Path input is derived from user args and internal globbing.
Suspicious network request
NPS-BE5A0D219DDB
The code sends an OIDC token in an Authorization header to an environment-provided URL (ACTIONS_ID_TOKEN_REQUEST_URL). If an attacker controls this environment variable, tokens could be exfiltrated to a malicious endpoint. However, GitHub Actions sets this variable, and the code only trusts it in GITHUB_ACTIONS context.
Redaction bypass on sensitive output
NPS-D59CFD2092E1
The outputMsg function explicitly disables redaction ({ redact: false }) when printing the URL, with a comment stating that URLs are sometimes login URLs. This intentionally bypasses npm's log redaction, so any credentials or tokens embedded in the URL (e.g. auth tokens in query parameters) will be printed to standard output/logs, potentially leaking secrets.
Unvalidated URL opening in browser
NPS-D7FA7241DD62
The openUrl function uses the @npmcli/promise-spawn 'open' helper to launch a URL in the user's web browser. While assertValidUrl restricts the protocol to http/https, the URL is fully controlled by the caller and passed directly to the browser opener. If a caller supplies a crafted URL, this could open arbitrary web content in the user's browser, which is a potential phishing or drive-by vector. Additionally, isFile=true skips protocol validation entirely, allowing arbitrary strings (including file:// URLs) to reach the browser opener.
User-controlled browser command execution
NPS-28ADAAF20635
The 'browser' configuration value from npm config is passed as the 'command' option to @npmcli/promise-spawn's open(). If an attacker can influence npm config (e.g. via a malicious .npmrc or environment variable), this could cause an arbitrary binary to be spawned with the URL as an argument. This is a potential command execution surface depending on how npm config is sourced.
Environment Interaction
NPS-AF870D0A8D6A
The script references npm configuration definitions via @npmcli/config but does not read, harvest, or transmit any environment variables, .npmrc files, or credentials to external servers.
Dynamic Module Loading
NPS-44A1B25B724D
Uses require() to load local relative paths ('../lib/cli.js', './npm-cli.js') and a fixed package path ('@npmcli/config/lib/definitions'). These are static, hardcoded paths with no computed or external input, so there is no dynamic import risk.
Process Argument Manipulation
NPS-ECBEF94E0846
The script modifies process.argv to route npx arguments to npm exec. This is legitimate argument preprocessing, not malicious. It only manipulates the argument array in memory and does not execute external commands, read credentials, or exfiltrate data.
Potential command execution via dynamic require
NPS-0EC7958C8D35
In replaceDefinitions, getCommand(name, commandLoader) is called with name derived from the doc file path (basename stripped of npm- prefix and .md extension). If doc file names were attacker-controlled, this could allow requiring arbitrary modules under lib/commands, potentially executing arbitrary code on import.
import-time-code-execution
NPS-C50783164183
Top-level code runs immediately on import: enableCompileCache() is invoked and validateEngines/require chains are wired up. This is normal CLI bootstrap behavior but means the package executes logic at import time, so the full transitive code path (validate-engines.js and cli/entry.js) must be reviewed for malicious behavior since this file alone cannot be judged safe.
dynamic-module-loading
NPS-A9723E7D11DA
The module resolves and requires an entry point (cli/entry.js) using a path computed at runtime via __dirname. While the path is deterministic and package-local, this pattern dynamically loads a module rather than a static import, which can obscure what code actually executes. In this file the target is fixed, so the risk is limited, but the pattern warrants verification that cli/entry.js and validate-engines.js contain no malicious payloads.
process_spawn
NPS-743B1F1E8871
The edit subcommand spawns the user-configured editor process (this.npm.flatOptions.editor) on the npmrc file. This is intentional functionality for npm config edit, uses explicit user-provided config, and does not execute untrusted input or perform hidden actions.
network_request
NPS-57748EB0E002
Uses pacote/npmFetch to query the configured npm registry for the latest npm package manifest and to ping the registry. This is expected behavior for an npm CLI health-check tool.
network_request
NPS-79D77AF5A2D9
Makes an HTTPS GET request to 'https://nodejs.org/dist/index.json' to fetch Node.js release information. This is a legitimate, expected behavior for an npm doctor command and does not involve sending any local data outbound.
filesystem_access
NPS-A32E4AC8FFC5
Recursively traverses npm cache, local/global node_modules, and local/global bin directories to verify permissions. This is scoped to npm-related directories and is the documented purpose of the doctor command.
subprocess_spawn
NPS-A79D7484D810
Uses the 'which' module to locate the 'git' executable in PATH. This does not spawn a shell or execute arbitrary commands; it only resolves the binary path.
filesystem_write
NPS-C283721269BF
cacache.verify is invoked on the npm cache, which may garbage-collect corrupted content. This is a standard npm cache maintenance operation and is confined to the npm cache directory.
path resolution / workspace handling
NPS-5FA55C1D1B0D
Custom resolution of localBin and pkgPath for workspaces using resolve(runPath, 'node_modules', '.bin') and workspace paths. No external data exfiltration, but it manipulates filesystem paths outside the immediate module scope based on workspace configuration.
install script execution
NPS-39AEF203EE7E
The command explicitly sets packageLockOnly: false so that missing packages are actually installed when exec'd, which may trigger install scripts (lifecycle scripts). It also resolves allow-scripts policy from user/global config, deliberately skipping project-level config. This is behavior consistent with npm exec but represents code that can trigger arbitrary package install scripts.
Potential path traversal mitigation
NPS-B843AF0D8231
The code attempts to prevent path traversal using join('/', pkgname) and checking relative(path, this.npm.dir) === ''. However, the check may be insufficient if pkgname contains multiple path segments or encoded characters. This is a security-relevant pattern but appears to be a mitigation rather than a vulnerability.
Process exit code manipulation
NPS-690B4D261F48
The catch handler sets process.exitCode based on error codes from executed commands. This is normal error handling but interacts with arbitrary command execution.
Dynamic Import
NPS-DBE1D5CDD8FD
The code uses require('@npmcli/arborist') inside the exec method. This is a legitimate npm library used for managing package trees, not a malicious dynamic import.
Network Request
NPS-7D754F0A0809
The code uses pacote.manifest to fetch package metadata. This is standard behavior for npm commands that need to retrieve package information from registries.
URL Opening
NPS-593CE6D23D4A
The openUrl function opens funding URLs in the user's browser. This is expected behavior for the npm fund command, which retrieves and displays funding information for packages. The URLs come from package funding metadata, not from attacker-controlled external servers.
dynamic-file-globbing-from-user-input
NPS-C10E24484C3D
User-supplied arguments are used to build a glob pattern (via deref(args[0]) and string interpolation) that scans the filesystem under npm.npmRoot. While rooted/normalized through path.resolve, it uses attacker-influenced text in glob patterns.
Legitimate npm CLI functionality
NPS-796122C50E15
This file is part of the npm CLI's org command implementation. It uses libnpmorg (an official npm library) to manage npm organizations. All operations (set, rm, ls) are expected org management commands that require authentication via the otplease wrapper. No malicious patterns such as data exfiltration, credential harvesting, obfuscation, crypto mining, backdoors, or process spawning were detected.
network requests to npm registry
NPS-32EE2D946838
The code makes HTTP requests to the npm registry for legitimate purposes: fetching package metadata (pacote.packument) and user info (npmFetch.json on /-/user/org.couchdb.user:...). These are expected for the 'npm owner' command and use the user's configured registry, not hardcoded external servers.
package mutation via PUT request
NPS-F0361D2EB2CB
The changeOwners method sends a PUT request to update package maintainers. This is the intended functionality of 'npm owner add/rm' and is properly authenticated via otplease. No malicious data injection or exfiltration.
credential handling
NPS-075F1CA27E50
Authentication tokens are handled through npm's standard flatOptions and otplease utilities. No direct credential reading from files (.npmrc, etc.) or environment variables is performed in this file.
Dynamic module loading
NPS-2CDF90E0D008
Dynamically requires @npmcli/arborist. This is a standard dependency for npm's arborist functionality and is expected within npm's own codebase.
File system manipulation
NPS-29790BA39C60
Uses unlink to remove the old package-lock.json after renaming to npm-shrinkwrap.json. This is expected behavior for the npm shrinkwrap command and operates within the package directory.
Dynamic module loading
NPS-A2B19045E24D
The static cmd() method loads command modules via require(./commands/${command}) where command comes from deref(c). This is standard npm CLI architecture for dispatching to built-in commands (which are validated by deref against a known command list), not external input. It allows arbitrary command name strings to be passed, but this is an established, intended pattern in npm itself.
Process spawning / which
NPS-BBE07FC70CF0
Uses which(process.argv[0]) to resolve the node binary, and updates process.execPath/config.execPath to the resolved path. This is a normal npm startup routine to ensure correct node symlink resolution; it does not spawn shell commands or pass untrusted input to a shell.
Environment variable / process.title manipulation
NPS-59C93413A295
Sets process.title using only positional args and applies redactLog (replaceInfo) to cooked argv before logging. The comment explains this is done to prevent secrets from leaking into the process title/command line. This is a defensive, security-conscious behavior, not a harvesting pattern.
File system writes outside package scope
NPS-D40ACD3DC13E
Writes error report files to ${this.logPath}${file} (defaults to logs-dir under cache) and creates cache/logs directories via fs.mkdir with recursive:true. These are standard npm runtime paths (cache dir, logs dir) controlled by user config, not suspicious external locations.
Dynamic module loading
NPS-BA68827CA42D
The code uses require('hosted-git-info') inside the hostedFromMani method, which is a dynamic require based on a hardcoded string. This is not a red flag, but rather a common pattern in Node.js packages to lazy-load dependencies. The module loaded is a well-known, trusted package for parsing hosted git URLs.
Potential URL opening
NPS-44609CB78911
The code uses openUrl to open URLs derived from package manifests. This is a legitimate feature for npm CLI commands like 'npm bugs' or 'npm docs'. The URL is constructed from package metadata and passed to a utility that opens the user's browser. While this could theoretically be abused if a malicious package manifest contains a crafted URL, the manifest is fetched via pacote from the configured registry, and the user explicitly invokes the command, so the risk is low.
setBlocking direct stream manipulation
NPS-DAB9C39E1C7E
Calls stream._handle.setBlocking(true) on stdout/stderr TTY handles. This is a documented workaround copied from the yargs/set-blocking package, not a vulnerability.
Install-time code execution
NPS-6A981AB66927
Constructor registers process-level event listeners ('log', 'output', 'input') and sets up a Progress spinner immediately upon instantiation. This is standard npm CLI display logic, but it does mean module-level/side-effect behavior occurs on import/instantiation. No data is sent externally or executed unsafely.
Dynamic import
NPS-125F0642F3B8
Uses dynamic import() for 'chalk' and 'supports-color' inside the async load() method. These are static, hardcoded module names from trusted dependencies, not computed or external input.
Redaction bypass flag
NPS-EEE71720DD16
The code explicitly sets redact: false for 'notice' level logs and for JSON output buffering after per-item redaction. This is intentional per comments (2FA links, already-redacted items), but could theoretically weaken redaction if misused. Not malicious.
Environment variable and credential harvesting
NPS-46B82EBB1FEB
The code reads process.env.NPM_ID_TOKEN, process.env.ACTIONS_ID_TOKEN_REQUEST_URL, process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN, and process.env.SIGSTORE_ID_TOKEN. While these are OIDC-related tokens intended for authentication, the code collects and uses them to authenticate with the npm registry and enables token exchange. This is consistent with its stated purpose but constitutes credential handling that should be scrutinized.
Credential usage and propagation
NPS-76E57B749FA0
The retrieved npm token is stored in opts[authTokenKey] and config.set(authTokenKey, response.token, 'user'), effectively injecting a live auth token into the npm configuration for the session. This is expected behavior for OIDC publishing but could be abused if the token exchange endpoint or registry is malicious.
Dynamic URL construction
NPS-21166466E24C
new URL(/-/npm/v1/oidc/token/exchange/package/${escapedPackageName}, registry) concatenates package name into a URL path. While npa(...).escapedName is used, this pattern can lead to SSRF if registry or packageName are attacker-controlled, though typically they are user-specified.
JWT parsing without verification
NPS-8C077F78E522
The code decodes the OIDC idToken payload (base64) and parses JSON without verifying the signature. This is only used to decide whether to enable provenance based on visibility claims โ not for security-critical authorization โ but relying on unverified claims could be a logic flaw.
File write to package scope
NPS-A85BB7D95710
Writes an npmrc file into the installed npm package directory during global installs. This is intentional npm behavior to preserve builtin config, not a malicious pattern, and is scoped to the installed npm package path.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| docs/lib/index.js | medium | This is legitimate npm documentation tooling with no clear malicious intent, but it contains dynamic require() calls using computed paths derived from filenames/inputs, which is a minor security concern if those inputs are untrusted. |
| lib/cli.js | medium | The file contains no direct malicious patterns (no exfiltration, credential harvesting, eval, shell spawning, or network calls), but it dynamically loads cli/entry.js and validate-engines.js at import time, so those dependencies require review to confirm overall safety. |
| lib/commands/edit.js | medium | No overtly malicious code, but the command spawns external processes based on user-configurable input and triggers package lifecycle scripts, which poses moderate risk. |
| lib/commands/exec.js | medium | This is the legitimate npm exec command implementation; it intentionally executes commands and installs packages, but there is no evidence of data exfiltration, credential harvesting, obfuscation, or backdoor installation. |
| lib/commands/explore.js | medium | This is legitimate npm CLI code for the explore command that intentionally executes arbitrary commands in package directories; no malicious exfiltration, credential harvesting, or obfuscation was detected, though the command execution pattern is inherently high-risk. |
| lib/commands/help.js | medium | This npm CLI help command is legitimate but spawns system processes (man/emacsclient) and builds glob paths from user input, presenting a low/medium injection risk if paths were untrusted. |
| lib/utils/oidc.js | medium | The code is a legitimate OIDC token exchange implementation for npm publishing, but it handles sensitive CI tokens and constructs network requests with environment-provided URLs, warranting a warning-level review. |
| lib/utils/open-url.js | medium | No overtly malicious code (no exfiltration, credential harvesting, obfuscation, or install-time execution) was found, but the module intentionally disables log redaction for URLs and passes user/config-influenced values to a browser opener, creating credential-leak and command-spawning risk surfaces. |
| bin/npm-cli.js | safe | No malicious patterns detected |
| bin/npm-prefix.js | safe | No malicious patterns detected; the script only loads npm configuration to output the global prefix. |
| bin/npx-cli.js | safe | The npx CLI wrapper performs legitimate argument rewriting to delegate to npm exec and contains no malicious patterns such as exfiltration, credential harvesting, code execution, or backdoor behavior. |
| index.js | safe | This is a benign npm CLI entry point that runs the CLI only when executed directly and throws an error if used as a library API, with no malicious patterns. |
| lib/arborist-cmd.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/base-cmd.js | safe | No malicious patterns detected; the file contains legitimate npm CLI base command logic with no exfiltration, credential harvesting, obfuscation, or process execution. |
| lib/cli/entry.js | safe | No malicious patterns detected; the code is a standard npm CLI entry point with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| lib/cli/exit-handler.js | safe | No malicious patterns detected; the code is a legitimate npm CLI exit handler that manages process lifecycle events, error logging, and exit codes without any suspicious external calls, credential access, or dynamic code execution. |
| lib/cli/update-notifier.js | safe | No malicious patterns detected; the code is a legitimate npm update notifier that checks for new versions via pacote and writes a timestamp file in the npm cache directory. |
| lib/cli/validate-engines.js | safe | No malicious patterns detected |
| lib/commands/access.js | safe | No malicious patterns detected; the code is a legitimate npm CLI access command implementation with proper input validation and no exfiltration, credential harvesting, or dynamic execution. |
| lib/commands/adduser.js | safe | No malicious patterns detected |
| lib/commands/approve-scripts.js | safe | No malicious patterns detected |
| lib/commands/audit.js | safe | This is the legitimate npm CLI audit command implementation; it performs security audits via @npmcli/arborist and npm-audit-report with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors. |
| lib/commands/bugs.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/commands/cache.js | safe | No malicious patterns detected; the code is a legitimate npm CLI cache management module with expected file system and package registry interactions. |
| lib/commands/ci.js | safe | No malicious patterns detected; the file is a standard npm CLI 'ci' command implementation that validates lockfiles, manages node_modules, runs lifecycle scripts, and uses trusted @npmcli dependencies. |
Show 117 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/commands/completion.js | safe | No malicious patterns detected; this is legitimate npm tab-completion code that reads shell environment variables and local config files without any exfiltration, obfuscation, or process spawning. |
| lib/commands/config.js | safe | This is the legitimate npm CLI config command implementation with expected protected-field redaction; the only process spawn is the user-controlled editor for npm config edit and no exfiltration, credential harvesting, obfuscation, or backdoor patterns are present. |
| lib/commands/dedupe.js | safe | No malicious patterns detected; the file is a legitimate npm CLI dedupe command implementation with standard module imports and no data exfiltration, credential harvesting, obfuscation, or unauthorized process execution. |
| lib/commands/deny-scripts.js | safe | No malicious patterns detected; the file only defines a simple CLI command subclass with no executable or suspicious behavior. |
| lib/commands/deprecate.js | safe | The deprecate command implementation is standard npm CLI functionality that interacts only with the configured npm registry using authenticated requests and contains no malicious patterns. |
| lib/commands/diff.js | safe | This is the standard npm CLI diff command implementation; it contains no malicious patterns, obfuscation, credential harvesting, or unauthorized network/process activity. |
| lib/commands/dist-tag.js | safe | This file is a legitimate npm CLI dist-tag command implementation with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution. |
| lib/commands/docs.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/commands/doctor.js | safe | This file is the legitimate npm CLI 'doctor' command implementation; it contains no env-var harvesting, no obfuscation, no eval/dynamic execution, no credential theft, and no suspicious exfiltration, only expected registry pings, Node.js version checks, PATH lookups, and scoped filesystem permission checks. |
| lib/commands/explain.js | safe | No malicious patterns detected; the code is a normal npm CLI explain command implementation. |
| lib/commands/find-dupes.js | safe | No malicious patterns detected; the code is a standard npm CLI command implementation that delegates to the dedupe command with a dry-run setting. |
| lib/commands/fund.js | safe | The code appears to be a legitimate implementation of the npm fund command with no malicious patterns detected; all network and URL operations are expected for retrieving and displaying package funding information. |
| lib/commands/get.js | safe | This is a benign npm CLI subcommand implementation that delegates to the built-in 'npm config get' command with no malicious patterns. |
| lib/commands/help-search.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/commands/init.js | safe | This is the legitimate npm CLI init command implementation with no malicious patterns detected. |
| lib/commands/install-ci-test.js | safe | No malicious patterns detected |
| lib/commands/install-scripts.js | safe | No malicious patterns detected |
| lib/commands/install-test.js | safe | This file is a thin CLI command wrapper that delegates to npm install and test; no malicious patterns, exfiltration, obfuscation, or suspicious process execution detected. |
| lib/commands/install.js | safe | Legitimate npm CLI install command implementation with no malicious patterns detected. |
| lib/commands/link.js | safe | This is the standard npm CLI 'link' command implementation with no malicious patterns; it only performs expected package linking operations and script policy gating. |
| lib/commands/ll.js | safe | No malicious patterns detected; the file is a simple command implementation that extends an existing 'ls' command to set a 'long' config flag. |
| lib/commands/login.js | safe | No malicious patterns detected; the code is a standard npm login command that handles credentials securely through the official npm configuration and auth utilities. |
| lib/commands/logout.js | safe | No malicious patterns detected; the code implements legitimate npm logout functionality using standard registry fetch and config APIs. |
| lib/commands/ls.js | safe | The file is the standard npm 'ls' command implementation that only reads and prints the local dependency tree, with no network calls, credential access, obfuscation, or process spawning. |
| lib/commands/org.js | safe | The file implements standard npm org management commands using official libraries and contains no malicious code. |
| lib/commands/outdated.js | safe | No malicious patterns detected; this is a legitimate npm CLI 'outdated' command implementation that only performs expected registry queries via pacote. |
| lib/commands/owner.js | safe | This is a legitimate npm CLI command implementation for managing package owners; no malicious patterns were detected. |
| lib/commands/pack.js | safe | No malicious patterns detected; the code is a legitimate npm pack command implementation using expected libraries and APIs. |
| lib/commands/ping.js | safe | No malicious patterns detected; the code is a standard npm registry ping command that redacts sensitive registry URLs and uses legitimate npm utility modules. |
| lib/commands/pkg.js | safe | No malicious patterns detected; the code is a legitimate npm CLI command for managing package.json without any exfiltration, obfuscation, or suspicious behavior. |
| lib/commands/prefix.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/commands/profile.js | safe | No malicious patterns detected; the code is the standard npm CLI profile command implementation with expected registry interactions and no exfiltration or obfuscation. |
| lib/commands/prune.js | safe | No malicious patterns detected; the file is a standard npm CLI prune command implementation with no suspicious behavior. |
| lib/commands/publish.js | safe | No malicious patterns detected; this is the standard npm CLI publish command implementation with expected credential handling through npm's own config/auth utilities. |
| lib/commands/query.js | safe | No malicious patterns detected; the code implements a legitimate npm query command without data exfiltration, credential harvesting, or dynamic code execution. |
| lib/commands/rebuild.js | safe | No malicious patterns detected; this is a legitimate npm CLI rebuild command implementation. |
| lib/commands/repo.js | safe | No malicious patterns detected; the code only normalizes repository URLs for browser opening and performs no network, filesystem, process, or dynamic execution operations. |
| lib/commands/restart.js | safe | This is a simple lifecycle command wrapper class with no malicious patterns, external data handling, or dynamic code execution. |
| lib/commands/root.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/commands/run.js | safe | This is the legitimate npm CLI 'run' command implementation; it executes user-defined package scripts via the official @npmcli/run-script library, with no data exfiltration, obfuscation, credential harvesting, or other malicious patterns. |
| lib/commands/sbom.js | safe | No malicious patterns detected |
| lib/commands/search.js | safe | No malicious patterns detected |
| lib/commands/set.js | safe | No malicious patterns detected; the file is a simple npm CLI command wrapper that delegates to the built-in config command. |
| lib/commands/shrinkwrap.js | safe | The code is a standard npm command implementation for shrinkwrap, with no malicious patterns detected; the file operations and dynamic require are consistent with expected npm functionality. |
| lib/commands/stage/approve.js | safe | No malicious patterns detected |
| lib/commands/stage/download.js | safe | No malicious patterns detected |
| lib/commands/stage/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/commands/stage/list.js | safe | No malicious patterns detected |
| lib/commands/stage/publish.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/commands/stage/reject.js | safe | The code is a legitimate npm CLI command for rejecting a staged package; it uses standard registry fetch, OTP handling, UUID validation, and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| lib/commands/stage/view.js | safe | No malicious patterns detected; the code is a straightforward npm CLI command that validates a UUID, fetches stage data from the configured registry, and outputs it. |
| lib/commands/star.js | safe | Legitimate npm CLI star/unstar command implementation with no malicious patterns detected |
| lib/commands/stars.js | safe | The code is a legitimate npm CLI command for viewing starred packages, with no malicious patterns detected. |
| lib/commands/start.js | safe | This is a benign npm CLI command definition that extends LifecycleCmd to run a package's 'start' script; no malicious patterns, obfuscation, exfiltration, or dynamic execution were detected. |
| lib/commands/stop.js | safe | No malicious patterns detected |
| lib/commands/team.js | safe | No malicious patterns detected |
| lib/commands/test.js | safe | No malicious patterns detected |
| lib/commands/token.js | safe | No malicious patterns detected; the code is a legitimate npm CLI token management command. |
| lib/commands/trust/circleci.js | safe | No malicious patterns detected; the code is a legitimate npm CLI trust command for configuring CircleCI OIDC trust relationships with proper input validation. |
| lib/commands/trust/github.js | safe | No malicious patterns detected; the file is a benign npm CLI trust command definition for GitHub Actions with no network, filesystem, process, or dynamic execution risks. |
| lib/commands/trust/gitlab.js | safe | No malicious patterns detected; the file is a legitimate CLI command definition for managing GitLab CI/CD trusted publishing relationships with no external data transmission, credential harvesting, obfuscation, or dynamic execution. |
| lib/commands/trust/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/commands/trust/list.js | safe | No malicious patterns detected |
| lib/commands/trust/revoke.js | safe | No malicious patterns detected; the code is a legitimate npm CLI trust revoke command using standard registry API calls without credential harvesting, obfuscation, or backdoor behavior. |
| lib/commands/undeprecate.js | safe | No malicious patterns detected |
| lib/commands/uninstall.js | safe | No malicious patterns detected; the file is a standard npm CLI uninstall command implementation that uses the official @npmcli/arborist library for package removal. |
| lib/commands/unpublish.js | safe | No malicious patterns detected; this is the legitimate npm CLI unpublish command source code. |
| lib/commands/unstar.js | safe | No malicious patterns detected |
| lib/commands/update.js | safe | No malicious patterns detected; the file is a legitimate npm CLI update command implementation. |
| lib/commands/version.js | safe | No malicious patterns detected; the code is a standard npm version command implementation with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| lib/commands/view.js | safe | This is the standard npm CLI view command implementation with no malicious patterns detected; it performs expected registry metadata fetching and display without exfiltration, credential harvesting, or code execution. |
| lib/commands/whoami.js | safe | No malicious patterns detected |
| lib/lifecycle-cmd.js | safe | No malicious patterns detected; the file is a simple command wrapper that delegates to npm's internal exec method. |
| lib/npm.js | safe | This is the standard npm CLI entry file (lib/npm.js) from the npm package; it shows no exfiltration, credential harvesting, obfuscation, backdoors, or other malicious patterns, only expected CLI/config behaviors with defensive title/log redaction. |
| lib/package-url-cmd.js | safe | This file is a legitimate npm CLI utility for opening package URLs and contains no malicious patterns. |
| lib/trust-cmd.js | safe | No malicious patterns detected; the code is a legitimate npm CLI command for managing trusted publishing configurations and only communicates with the npm registry using standard npm libraries. |
| lib/utils/allow-scripts-cmd.js | safe | No malicious patterns detected |
| lib/utils/allow-scripts-prune.js | safe | No malicious patterns detected |
| lib/utils/allow-scripts-remediation.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/allow-scripts-writer.js | safe | No malicious patterns detected; the module only contains pure helper functions for managing npm's allowScripts policy and does not perform network, filesystem, process, or dynamic code execution operations. |
| lib/utils/audit-error.js | safe | No malicious patterns detected in the audit-error utility module. |
| lib/utils/auth.js | safe | Legitimate npm authentication utility that handles login/adduser flows with OTP prompts; no malicious patterns detected. |
| lib/utils/check-allow-scripts.js | safe | No malicious patterns detected; the code is a benign wrapper around arborist's script collection utility. |
| lib/utils/cmd-list.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/did-you-mean.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/display.js | safe | This is legitimate npm CLI display/formatting utility code with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution. |
| lib/utils/error-message.js | safe | No malicious patterns detected; the file is standard npm CLI error formatting logic with no exfiltration, credential harvesting, or dynamic code execution. |
| lib/utils/explain-dep.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/explain-eresolve.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/format-bytes.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/format-search-stream.js | safe | No malicious patterns detected; the module only formats and streams package search results with no network, filesystem, process, or dynamic code execution activity. |
| lib/utils/format.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/get-identity.js | safe | The code retrieves npm authentication credentials from the user's npm configuration and queries the registry's /-/whoami endpoint to obtain the username, which is standard npm CLI behavior with no malicious patterns detected. |
| lib/utils/get-workspaces.js | safe | No malicious patterns detected; the code is a legitimate workspace resolver using standard npm packages with no network, credential, process, or obfuscation activity. |
| lib/utils/installed-deep.js | safe | No malicious patterns detected; the code is a standard npm utility for listing installed packages. |
| lib/utils/installed-shallow.js | safe | No malicious patterns detected; the module simply lists installed packages using npm's local/global directories. |
| lib/utils/is-windows.js | safe | No malicious patterns detected; the code is a simple platform/terminal detection utility with no network, filesystem, or execution side effects. |
| lib/utils/key-values.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/log-file.js | safe | No malicious patterns detected |
| lib/utils/npm-usage.js | safe | No malicious patterns detected |
| lib/utils/output-error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/ping.js | safe | This file is a benign utility that pings the npm registry using the standard npm-registry-fetch library, with no malicious patterns, data exfiltration, or credential harvesting. |
| lib/utils/queryable.js | safe | No malicious patterns detected; the code is a legitimate utility for safely querying and modifying nested object properties with prototype-pollution protections. |
| lib/utils/read-user-info.js | safe | No malicious patterns detected; the code handles user input for OTP, password, username, and email prompts using the 'read' and 'npm-user-validate' libraries without any exfiltration, obfuscation, or suspicious behavior. |
| lib/utils/reify-finish.js | safe | The file performs expected npm reify finalization tasks (preserving global npm config, checking/warning about allow-scripts) with no malicious indicators such as exfiltration, credential theft, obfuscation, or shell execution. |
| lib/utils/reify-output.js | safe | No malicious patterns detected; the file is legitimate npm CLI output logic that formats install/audit summaries without network, credential, or code-execution behavior. |
| lib/utils/resolve-allow-scripts.js | safe | No malicious patterns detected; the code is a legitimate npm configuration resolver for allow-scripts policy with no exfiltration, dynamic execution, or suspicious process spawning. |
| lib/utils/sbom-cyclonedx.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/sbom-spdx.js | safe | The code generates SPDX SBOM output from npm dependency trees without any malicious patterns, network requests, credential harvesting, or process execution. |
| lib/utils/strict-allow-scripts-preflight.js | safe | No malicious patterns detected; the file performs an npm strict-allow-scripts pre-flight check using only local arborist and helper modules, with no network, filesystem, or process-spawning activity. |
| lib/utils/tar.js | safe | No malicious patterns detected; the code is a benign tarball inspection utility that reads package contents, computes integrity, and logs metadata without external network, credential, or execution risks. |
| lib/utils/timers.js | safe | No malicious patterns detected |
| lib/utils/update-workspaces.js | safe | No malicious patterns detected |
| lib/utils/validate-lockfile.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/validate-uuid.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/verify-signatures.js | safe | This is npm CLI's legitimate signature verification module that fetches public keys and verifies package signatures via Sigstore TUF and the npm registry; no malicious patterns, exfiltration, or credential harvesting detected. |
| lib/utils/warn-workspace-allow-scripts.js | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is npm safe to use?
No confirmed malware was found in npm@11.19.0, but the review flagged 11 medium, 41 low severity findings for risky patterns worth checking before you rely on it.
Does npm contain malware?
No malware was identified in npm@11.19.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was npm checked?
Togoder Security downloaded the published npm package and had an AI model read its 142 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan npm together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in npm@11.19.0, cost nothing.